CVE-2021-24507

CRITICAL

Astra Pro Addon < 3.5.2 - SQL Injection via astra_pagination_infinite and astra_shop_pagination_infinite AJAX Actions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-24507. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-24507, an unauthenticated SQL injection vulnerability in Astra Pro Addon versions before 3.5.2. The exploit automates the extraction of a nonce and tests for both error-based and boolean-based SQL injection.

Description

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

Exploits (1)

nomisec WORKING POC
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2021-24507

This repository contains a functional exploit for CVE-2021-24507, an unauthenticated SQL injection vulnerability in Astra Pro Addon versions before 3.5.2. The exploit automates the extraction of a nonce and tests for both error-based and boolean-based SQL injection.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Astra Pro Addon < 3.5.2
No auth needed
Prerequisites: Target URL with vulnerable Astra Pro Addon installation
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/a1a0dc0b-c351-4d46-ac9b-b297ce4d251c
Release Notes, Vendor Advisory x_refsource_misc
https://wpastra.com/changelog/astra-pro-addon/

Scores

CVSS v3 9.8
EPSS 0.1130
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
brainstormforce/astra < 3.5.2
Published Aug 09, 2021
Tracked Since Feb 18, 2026